Skip to main content

PayPal: Steer Clear of Apple’s Safari

PayPal: Steer Clear of Apple

Michael Barrett, PayPal‘s chief information and security officer, has a message for users of Apple’s Safari Web browser: don’t use it with PayPal, at least if you want to avoid online fraud. In an interview with PC World, Barrett laments that Safari doesn’t support two anti-phishing technologies that he says have accounted for a “several percentage-point” improvement in customers signing up for the service. “I’d love to say that Safari was a safer browser, but at this point it isn’t,” said Barrett.

Safari is the default Web browser under Mac OS X and on Apple’s Mobile OS X, used on the iPhone and iPod touch. Safari is also available for Windows.

Barrett takes Safari to task for not offering an anti-phishing filter that alerts users when they may be visiting suspicious sites. He would also like to see Safari and other browsers support Extended Validation certificates (EV), a technology currently only supported right now in Internet Explorer 7, although Firefox 3.0 plans to implement it. Barrett recommends PayPal users stick with IE 7, FireFox 2 or 3, or Opera. “Apple, unfortunately, is lagging behind what they need to do, to protect their customers,” Barrett said.

Anti-phishing filters turn a browser’s address bar green when a user is visiting a site the technology believes is legitimate. Allegedly fraudulent sites highlight the address bar in red, while suspicious sites will be marked with yellow. The technologies have received some criticism for being biased towards large enterprises, and for potential vulnerabilities that may let attackers game the systems to misrepresent arbitrary sites. Microsoft’s phishing filter relies on a database of sites “confirmed by reputable sources” to be fraudulent.

A small usability study of anti-phishing technologies conducted by Microsoft and Stanford University found that, without training, users weren’t likely to notice or understand the green address bar on approved sites.

Editors' Recommendations

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Here’s why WWDC could be a ‘critical event’ for Apple
Apple CEO Tim Cook looks at a display of brand new redesigned MacBook Air laptop during the WWDC22

Apple is planning a packed line-up for its Worldwide Developers Conference (WWDC) on June 5, which could become “one of the most critical events in the company’s history.” Aside from the company’s upcoming Reality Pro headset, there will be major updates to Apple’s software systems, including the biggest watchOS revamp since the Apple Watch launched in 2015.

That’s according to a new report from Bloomberg journalist Mark Gurman, who has a history of accurate predictions and leaks surrounding Apple products. It suggests that WWDC will be a chance for Apple to set out its future ambitions for a “post-iPhone era.”

Read more
This major Apple bug could let hackers steal your photos and wipe your device
A physical lock placed on a keyboard to represent a locked keyboard.

Apple’s macOS and iOS are often considered to be more secure than their rivals, but that doesn’t make them invulnerable. One security team recently proved that by showing how hackers could exploit Apple’s systems to access your messages, location data, and photos -- and even wipe your device entirely.

The discoveries were published on the blog of security research firm Trellix, and will be of major concern to iOS and macOS users alike, since the vulnerabilities can be exploited on both operating systems. Trellix explains that Apple patched the exploits in macOS 13.2 and iOS 16.3, which were released in January 2023, so you should update your devices as soon as you can.

Read more
If you use PayPal, your personal data may have been compromised
A person holds a mobile phone with the PayPal app open.

PayPal has recently suffered a massive data breach, and if you were one of the affected users, your details may have been leaked. Given the nature of a PayPal account, the exposed data includes some of the most sensitive information, which could put those users at risk of identity theft.

The company is taking steps to protect the accounts from further damage. Here's what we know about what happened and how to protect yourself.

Read more